Dark River

2023-09-27 • PtsecurityDark River. You can't see them, but they're there

Positive Technologies identified this activity in October 2022 after investigating an intrusion at a Russian industrial enterprise, where it found a previously unseen modular backdoor it named MataDoor, and named the operator Dark River after the word River found in phishing-document author metadata. The likely initial vector was a phishing email with a DOCX attachment exploiting a Microsoft MSHTML vulnerability, sent to Russian defense-industry organizations in August and September 2022; researchers linked this wave to a similar September 2021 campaign using the same vulnerability and identical URL-encoding technique against Russian defense and government targets, indicating the actor has operated since at least 2021. Payloads and later backdoor samples were signed with Sectigo certificates and used Namecheap-registered command-and-control domains that did not overlap between victims. MataDoor is built around a kernel and functional and network plugins, uses AES-encrypted configuration data, and disguises its files as legitimate software already present on infected hosts. Kaspersky separately linked a related backdoor variant to Lazarus group activity, though Positive Technologies could not independently confirm the operator's identity.

Related Actors

Related Reports in This Cluster

Top Authors

View Dark River reports only

View Dark River reports only